Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Jérôme Meyer

@jmeyer@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Security research at Nokia Deepfield (he/they).

EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

0 Followers
0 Following
19 Posts
Joined November 09, 2022
Homepage:
https://med.ac/about
Signal:
jmeyer.01
Work account:
https://infosec.exchange/@deepfield
Open post
Jérôme Meyer @jmeyer@infosec.exchange
· 6mo ago

RE: @deepfield@infosec.exchange

The operator built triple-layer crypto, fast-flux DNS across 30+ ASes, biweekly C2 rotation — then shipped an unstripped debug build on port 8090, a couple of ports over from production. 300+ symbols, project name, internal module names, all right there in readelf.

Anyway here's the full writeup.

https://github.com/deepfield/public-research/blob/main/jackskid/report.md

#threatintel #ddos

infosec.exchange

Nokia Deepfield: "Most Mirai forks are disposable. #Jackskid was bu…" - Infosec Exchange

20
0
14
2
Open post
Jérôme Meyer @jmeyer@infosec.exchange
· 6mo ago

One custom RC4 seed led us to four botnets, five C2 channels, and a developer who shipped their Windows username and Cursor IDE logs with their malware.

Equal parts cryptography, thread-pulling, and easter eggs.

https://github.com/deepfield/public-research/blob/main/reports/2026-03-20-aisuru-ecosystem.md

#threatintel #Aisuru #kimwolf #jackskid #mossadproxy #cecilio

GitHub

public-research/reports/2026-03-20-aisuru-ecosystem.md at main · deepfield/public-research

DDoS botnet research and indicators of compromise from Nokia Deepfield ERT - deepfield/public-research

16
0
6
1
Open post
Jérôme Meyer @jmeyer@infosec.exchange
· 6mo ago

New, from our ERT: #CECbot, an Android TV botnet and the first malware we're aware of that exploits HDMI-CEC.

It puts the TV to sleep so you don't notice the box behind it is running DDoS and residential proxy traffic. Curve25519/ChaCha20 crypto, 9 persistence layers, and... LAN mapping.

Successor to a Mirai fork, shares not much but the C2 server.

https://github.com/deepfield/public-research/blob/main/cecbot/report.md

#threatintel #DDoS

GitHub

public-research/cecbot/report.md at main · deepfield/public-research

DDoS botnet research and indicators of compromise from Nokia Deepfield ERT - deepfield/public-research

12
0
13
0
Open post
Jérôme Meyer @jmeyer@infosec.exchange
· 6mo ago

New, from our @deepfield@infosec.exchange ERT: found a new botnet dressing its C2 traffic as camera management.

#Drifter names its domains after Hikvision products, blending with surveillance traffic on the same VLAN as the Android TV boxes it infects. DNS queries go through an Australian resolver, which somewhat undermines the cover if your bot is in São Paulo.

71 KB binary, already linked to attacks exceeding 2 Tbps from 80k sources. At least six operators are now competing for the same devices.

https://github.com/deepfield/public-research/blob/main/drifter/report.md

#threatintel #ddos

infosec.exchange

Nokia Deepfield (@deepfield@infosec.exchange) - Infosec Exchange

8
0
6
0
Open post
Jérôme Meyer @jmeyer@infosec.exchange
· 3mo ago
RE: https://infosec.exchange/@deepfield/116863154478881362 The part that didn’t make the report: nobody tipped us off. This was in our own telemetry the whole time and we, professionals, scrolled past it for months. one operator, two fleets, floods tasked through the proxy’s own 0x07 the entire time. Anyway nothing says “legitimate residential proxy” like calmly issuing an attack command against a full /15 of some ISP, totally normal, nothing to see, scroll on
infosec.exchange

Nokia Deepfield: "We’d genuinely rather write the other report: the…" - Infosec Exchange

2
0
1
0
Open post
Jérôme Meyer @jmeyer@infosec.exchange
· 5mo ago
Replying to
@campuscodi@mastodon.social Saw a ~6 Tbps attack this morning with about 5k hosting sources, which had one thing in common: cPanel
5
2
4
0
Open post
Jérôme Meyer @jmeyer@infosec.exchange
· 6mo ago

Other than publishing these botnet reports I’m enjoying my week off 🤣

3
2
0
0
Open post
Jérôme Meyer @jmeyer@infosec.exchange
· 6mo ago

The backstory of #Kimwolf, from our initial sightings early last year to how @synthient@cyberplace.social discovered the vuln that made that botnet possible.

https://www.wsj.com/tech/kimwolf-hack-residential-proxy-networks-a712ab59?st=3eNTjx

infosec.exchange

Infosec Exchange

2
2
0
0
Open post
Jérôme Meyer @jmeyer@infosec.exchange
· 6mo ago

RE: @deepfield@infosec.exchange

We dug into the binaries from a Xiongmai DVR proxyware campaign that @nicter_jp@bird.makeup wrote up. Mirai stripped for parts, PacketSDK with a dead dispatch chain, and a dormant RCE backdoor that's just... waiting.

Our report (which really is a companion piece to NICTER's): https://github.com/deepfield/public-research/blob/main/reports/2026-03-19-xiongmai-packetsdk-ipidea.md

#threatintel #IPIDEA

infosec.exchange

Nokia Deepfield: "Excellent work by @nicter_jp@bird.makeup document…" - Infosec Exchange

2
0
0
0
Open post
Jérôme Meyer @jmeyer@infosec.exchange
· 5mo ago
Replying to
@hrbrmstr congratulations on the new job! (And welcome to the Ann Arbor nexus)
1
0
0
0
Open post
Jérôme Meyer @jmeyer@infosec.exchange
· 5mo ago

New report from our ERT: #Maskify.

The operator built what a Series A deck would call "decentralized edge infrastructure": ENS for service discovery, IPFS for binary distribution, a custom P2P mesh network, QUIC transport.

In practice it is a DDoS botnet running on Android TV boxes that did not opt in.

https://github.com/deepfield/public-research/blob/main/maskify/report.md

#threatintel #ddos

infosec.exchange

Infosec Exchange

1
0
0
1
Open post
Jérôme Meyer @jmeyer@infosec.exchange
· 6mo ago

When a botnet operator names their payload after your team, you check the diff.

libcyn.so → deepfield.so
Custom cipher → wolfSSL TLS 1.3 (same stack as earlier Kimwolf)

C2 domains, floods, targets: all unchanged.

9a28696774d9ef6754540633daeef668767df5efa1804138abd35e1a6b31523e

#drifter #threatintel #ddos

infosec.exchange

Infosec Exchange

1
0
0
0
Open post
Jérôme Meyer @jmeyer@infosec.exchange
· 6mo ago
Replying to
@CyberPhilTrem@infosec.exchange 3 Vallées 💯
1
0
0
0
Open post
Jérôme Meyer @jmeyer@infosec.exchange
· 19mo ago
Replying to
@shadowserver @deepfield Thanks for the additional analysis, this is great. This lines up pretty well with what we’re seeing for bot counts (the deviation on Taiwan may be related to a slightly different device signature, looking into that now). Current count is approx 41k bots seen in attacks so far.
2
0
1
0
Open post
Jérôme Meyer @jmeyer@infosec.exchange
· 5mo ago
Replying to
@campuscodi @censys also notes in https://censys.com/blog/the-cpanel-situation-is/ that this may be related to a Mirai-derivative we have been tracking under Flameblox. I should be able to confirm that with the next attack commands.
The cPanel Situation Is… - Censys
Censys

The cPanel Situation Is… - Censys

CVE-2026-41940: Critical cPanel/WHM pre-auth bypass exploited within 24hrs. Censys research reveals Mirai variants, ".sorry" ransomware & mass automated attacks.

0
0
0
0
Open post
Jérôme Meyer @jmeyer@infosec.exchange
· 3mo ago
RE: https://infosec.exchange/@deepfield/116868970182801401 reversing the least threatening thing in my pipeline: they garbled the Go, hand-edited the headers, made it genuinely annoying in ghidra. it worked! it stopped me for a weekend! to reach a target list i’ve had a live feed of for YEARS the decryption key was a cookie they sent me. anyway
Open quoted post
Quoting
Nokia Deepfield
@deepfield@infosec.exchange
DDoSia is one of the least interesting botnets we track. We wrote it up anyway. Its product was never downtime. It’s the claim of downtime. We looked at the actual traffic. The honest version is boring. And boring is the one story the group can’t turn into a win. New from our ERT: https://github.com/deepfield/public-research/blob/main/ddosia/report.md #threatintel #NoName057
Open quoted post
infosec.exchange

Nokia Deepfield: "DDoSia is one of the least interesting botnets we…" - Infosec Exchange

0
2
0
0
Open post
Jérôme Meyer @jmeyer@infosec.exchange
· 2mo ago
RE: https://infosec.exchange/@deepfield/116959928537612450 “Not a mirai at all” it insists, from inside the mirai. the denial is honestly aspirational
Open quoted post
Quoting
Nokia Deepfield
@deepfield@infosec.exchange
New ERT report: #IranBot is a botnet built to be thrown away. Three builds in six weeks, no infrastructure reused, each one cruder and each one reaching further. The build stripped of encryption is the one worming today, and its C2 outlives none of the others by much. https://github.com/deepfield/public-research/blob/main/iranbot/report.md #threatintel #DDoS
Open quoted post
infosec.exchange

Nokia Deepfield: "New ERT report: #IranBot is a botnet built to be …" - Infosec Exchange

0
0
0
0
Open post
Jérôme Meyer @jmeyer@infosec.exchange
· 2mo ago
RE: https://infosec.exchange/@deepfield/116976577337745826 it infects your neighbour's router by guessing the telnet password and then politely asks your router to open 165 ports. one of those is a break in and the other is UPnP working exactly as designed. anyway it all comes back to one guy off a funding wallet and a config key he forgot to rotate. the cluster map is pepe silvia. this is my job.
Open quoted post
Quoting
Nokia Deepfield
@deepfield@infosec.exchange
New, from our ERT: Most residential proxy malware hides the exit behind an outbound tunnel. This one has the victim’s own router open 165 ports over UPnP and labels every mapping RELAY. Telemetry on the proxy domains led us back to #Jackskid, a DDoS botnet we have tracked since late 2025. Same operator behind all of it: a pure relay family, a Mirai bot that moonlights as one, and Jackskid, which now compiles the relay straight in. https://github.com/deepfield/public-research/blob/main/reports/2026-07-24-jackskid-residential-proxy-upnp.md #threatintel #tree4sale #peer4you
Open quoted post
infosec.exchange

Nokia Deepfield: "New, from our ERT: Most residential proxy malwar…" - Infosec Exchange

0
0
0
0
Open post
Jérôme Meyer @jmeyer@infosec.exchange
· 2mo ago
Replying to
@kr3st3n@infosec.exchange Indeed — they recommend volunteers run this behind a VPN, so we indeed mostly see exit nodes from a handful of VPN providers, for the most part.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:28:07 UTC